GRR please help me!

Discussion in 'Malware Help (A Specialist Will Reply)' started by clueless_pc_user, Apr 27, 2007.

  1. clueless_pc_user

    clueless_pc_user Private E-2

    :cry Hello, I am not sure I am even posting in the right place but here goes.
    As you can see by my screen name i have no clue when it comes to pc's.
    But what I have managed to figure out is that my ps is infected with something... My home page keeps changing I can not do a distructive resotre( I have tried and it remanes the same as before the restore) I have tried many different spywares, antivirus, adwares nothing seems to work. Any one have any clue...

    With some of the scans i have done these are some of the findings they say to remove

    win32.vb.atz
    backdoor.win32.sdbot.gen
    daugeru
    wildtangent
    avenuea,inc
    goclick

    please anyone ,
    and if am not posting this in the right board please if you know where i should post it let me no thank you in advance

    -CLUELESS
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. clueless_pc_user

    clueless_pc_user Private E-2

    Virus free? how do I know?

    Ok I am pretty sure I have removed all the virus and junk on my pc... How do i know for sure? should I do a factory restore now? I am so afraid of getting more. Any suggestions? like what software to use to protect my pc now that it is clean (i think)? Thank you so much
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Virus free? how do I know?

    The only way we can tell you if your PC is clean is if you you complete the instructions you were given in your other thread ( which is here: http://forums.majorgeeks.com/showthread.php?t=124745 ) Also you should have remained in that thread. This thread will be merged back with that one.

    If you do a factory restore, it will put the PC back into the state that it was when you received it. Anything you have installed since that time will be gone. Is that what you want to do? If so, why did you bother removing the malware.

    Are tips for helping you stay clean are in another one of the stickies which you should be reading:

    How to Protect yourself from malware!

    However you should not be doing the above until your PC has been verified to be clean.
     
  5. clueless_pc_user

    clueless_pc_user Private E-2

    Re: Virus free? how do I know?

    I am sorry i am stupid when it comes to pc's I tried to follow all of the advice that you gave... but some of the things wouldnt work... ( the getrunkey.zip)
    And my factory restore would not restore before I thought that it was because of the virus.... I am willing to go back to factory settings but it wouldnt let me thats why i came to you
     
  6. clueless_pc_user

    clueless_pc_user Private E-2

    Re: Virus free? how do I know?

    ok I am trying the instructions again and i still dont understand how to do the getrunkey.zip and the shownew.zip
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Virus free? how do I know?

    Have you completed all the other steps that were to be run before GetRunKey and ShowNew?

    What is the exact problem you are having with using GetRunKey and ShowNew? Are you following the directions in the download links that explain you need to unzip the files?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still cannot understand how to perform the steps to use GetRunKey and ShowNew. Try the below which should automatically installed and run the batch files to create the two logs for you.

    Please download the attached MGtools.exe file to your Desktop. And then double click on it to run it. If it works properly you should have the two log files now.

    Note: Just close the newfiles.txt log that should popup when it completes. Then look for c:\newfiles.txt and c:\runkeys.txt
    Are the files there? If yes, attach them. If not, did you receive any error messages.
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds